SQL Injection in report_xml.php through countryFilter[] parameter
Critical
V
Valve
Submitted None
Team Summary
Official summary from Valve
An unvalidated parameter on an partner reporting page (report_xml.php) could be used to read certain SQL data from a single backing database.
Actions:
Reported by
moskowsky
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Bounty
$25000.00
Submitted
Weakness
SQL Injection